CVE-2014-6277, also known as Shellshock, is a critical vulnerability in GNU Bash through version 4.3 that allows remote attackers to execute arbitrary code or cause a denial of service. This flaw stems from improper parsing of function definitions in environment variables, affecting scenarios like OpenSSH, Apache HTTP Server modules, and DHCP clients. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with low complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, its high EPSS score, FAUCET Risk Score, and extensive community discussion (15 mentions) indicate significant exploitability and attention. Exploit code is publicly available on ExploitDB, and it has received substantial media coverage, highlighting its widespread impact and the need for immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.0CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:* | ||
1.14.3CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:* | ||
1.14.4CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.